CVE-2025-4599

CVE Details

Basic Information

Title CVE-2025-4599
Type cve
Published 2025-08-04T21:18:14.251Z
Modified 2025-08-04T21:18:14.251Z

Product Information

Vendor Liferay
Product Portal
Version 7.4.0

CVSS Information

Base Score 2.0 (LOW)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

AI Analysis

AI Description A postMessage-based XSS vulnerability in Liferay Portal allows remote attackers to inject JavaScript into the fragment portlet URL, potentially leading to unauthorized actions.
AI Severity Medium
AI Vendor Liferay, Inc.
AI Product Liferay Portal
AI Version 7.4.0, 7.4.3.61, 7.4.3.132, 2024.Q1.1, 2024.Q2.0, 2024.Q3.0, 2024.Q4.0

Affected Products

  • Liferay Portal 7.4.0
  • Liferay DXP 7.4.13-u61
  • Liferay DXP 2024.Q1.1
  • Liferay DXP 2024.Q2.0
  • Liferay DXP 2024.Q3.0
  • Liferay DXP 2024.Q4.0

Additional Information

CWE List CWE-79
Source Liferay

Description

The fragment preview functionality in Liferay Portal 7.4.3.61 through 7.4.3.132, and Liferay DXP 2024.Q4.1 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.13 and 7.4 update 61 through update 92 was found to be vulnerable to postMessage-based XSS because it allows a remote non-authenticated attacker to inject JavaScript into the fragment portlet URL.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.